LWN.net Logo

pulseaudio: privilege escalation

Package(s):pulseaudio CVE #(s):CVE-2009-1894
Created:July 16, 2009 Updated:July 28, 2009
Description: PulseAudio has a local privilege escalation vulnerability. From the Gentoo alert:

Tavis Ormandy and Julien Tinnes of the Google Security Team discovered that the pulseaudio binary is installed setuid root, and does not drop privileges before re-executing itself. The vulnerability has independently been reported to oCERT by Yorick Koster. A local user who has write access to any directory on the file system containing /usr/bin can exploit this vulnerability using a race condition to execute arbitrary code with root privileges.

Alerts:
Mandriva MDVSA-2009:171 2009-07-28
Debian DSA-1838-1 2009-07-18
Mandriva MDVSA-2009:152 2009-07-17
Ubuntu USN-804-1 2009-07-16
Gentoo 200907-13 2009-07-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds